cbcvebase.

Google Chrome vulnerabilities

5,831 known vulnerabilities affecting google/chrome.

Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2

Vulnerabilities

Page 178 of 292
CVE-2012-2878P4HIGHCVSS 7.5≤ 22.0.1229.78v22.0.1229.0+51 more2012-09-26
CVE-2012-2878 [HIGH] CWE-399 CVE-2012-2878: Use-after-free vulnerability in Google Chrome before 22.0.1229.79 allows remote attackers to cause a Use-after-free vulnerability in Google Chrome before 22.0.1229.79 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to plug-in handling.
nvd
CVE-2012-5145P4HIGHCVSS 7.5≤ 24.0.1312.51v24.0.1272.0+119 more2013-01-15
CVE-2012-5145 [HIGH] CWE-416 CVE-2012-5145: Use-after-free vulnerability in Google Chrome before 24.0.1312.52 allows remote attackers to cause a Use-after-free vulnerability in Google Chrome before 24.0.1312.52 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to SVG layout.
nvd
CVE-2010-3111P4CRITICALCVSS 10.0≤ 6.0.472.532010-08-24
CVE-2010-3111 [CRITICAL] CVE-2010-3111: Google Chrome before 6.0.472.53 does not properly mitigate an unspecified flaw in the Windows kernel Google Chrome before 6.0.472.53 does not properly mitigate an unspecified flaw in the Windows kernel, which has unknown impact and attack vectors, a different vulnerability than CVE-2010-2897.
nvd
CVE-2014-7902P4HIGHCVSS 7.5v39.0.2171.632014-11-19
CVE-2014-7902 [HIGH] CWE-17 CVE-2014-7902: Use-after-free vulnerability in PDFium, as used in Google Chrome before 39.0.2171.65, allows remote Use-after-free vulnerability in PDFium, as used in Google Chrome before 39.0.2171.65, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted PDF document.
nvd
CVE-2011-1123P4HIGHCVSS 7.5fixed in 9.0.597.1072011-03-01
CVE-2011-1123 [HIGH] CWE-863 CVE-2011-1123: Google Chrome before 9.0.597.107 does not properly restrict access to internal extension functions, Google Chrome before 9.0.597.107 does not properly restrict access to internal extension functions, which has unspecified impact and remote attack vectors.
nvd
CVE-2011-3889P4HIGHCVSS 7.5fixed in 15.0.874.1022011-10-25
CVE-2011-3889 [HIGH] CWE-787 CVE-2011-3889: Heap-based buffer overflow in the Web Audio implementation in Google Chrome before 15.0.874.102 allo Heap-based buffer overflow in the Web Audio implementation in Google Chrome before 15.0.874.102 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2015-1346P4HIGHCVSS 7.5≤ 40.0.2214.852015-01-22
CVE-2015-1346 [HIGH] CVE-2015-1346: Multiple unspecified vulnerabilities in Google V8 before 3.30.33.15, as used in Google Chrome before Multiple unspecified vulnerabilities in Google V8 before 3.30.33.15, as used in Google Chrome before 40.0.2214.91, allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
nvd
CVE-2014-3194P4HIGHCVSS 7.5≤ 38.0.2125.72014-10-08
CVE-2014-3194 [HIGH] CWE-416 CVE-2014-3194: Use-after-free vulnerability in the Web Workers implementation in Google Chrome before 38.0.2125.101 Use-after-free vulnerability in the Web Workers implementation in Google Chrome before 38.0.2125.101 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2012-2833P4HIGHCVSS 7.5≤ 20.0.1132.42v20.0.1132.0+41 more2012-06-27
CVE-2012-2833 [HIGH] CWE-119 CVE-2012-2833: Buffer overflow in the JS API in the PDF functionality in Google Chrome before 20.0.1132.43 allows r Buffer overflow in the JS API in the PDF functionality in Google Chrome before 20.0.1132.43 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2012-5129P4HIGHCVSS 7.5v23.0.1271.91v23.0.1271.922012-12-04
CVE-2012-5129 [HIGH] CWE-119 CVE-2012-5129: Heap-based buffer overflow in the WebGL subsystem in Google Chrome OS before 23.0.1271.94 allows rem Heap-based buffer overflow in the WebGL subsystem in Google Chrome OS before 23.0.1271.94 allows remote attackers to cause a denial of service (GPU process crash) or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2010-4487P4HIGHCVSS 7.5fixed in 8.0.552.2152010-12-07
CVE-2010-4487 [HIGH] CVE-2010-4487: Incomplete blacklist vulnerability in Google Chrome before 8.0.552.215 on Linux and Mac OS X allows Incomplete blacklist vulnerability in Google Chrome before 8.0.552.215 on Linux and Mac OS X allows remote attackers to have an unspecified impact via a "dangerous file."
nvd
CVE-2015-1232P4HIGHCVSS 7.5≤ 40.0.2214.1152015-03-09
CVE-2015-1232 [HIGH] CVE-2015-1232: Array index error in the MidiManagerUsb::DispatchSendMidiData function in media/midi/midi_manager_us Array index error in the MidiManagerUsb::DispatchSendMidiData function in media/midi/midi_manager_usb.cc in Google Chrome before 41.0.2272.76 allows remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging renderer access to provide an invalid port index that triggers an out-of-bounds write operation, a different vul
nvd
CVE-2013-2843P4HIGHCVSS 7.5≤ 27.0.1453.91v27.0.1453.0+69 more2013-05-22
CVE-2013-2843 [HIGH] CWE-399 CVE-2013-2843: Use-after-free vulnerability in Google Chrome before 27.0.1453.93 allows remote attackers to cause a Use-after-free vulnerability in Google Chrome before 27.0.1453.93 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the handling of speech data.
nvd
CVE-2013-0920P4HIGHCVSS 7.5≤ 26.0.1410.42v26.0.1410.0+40 more2013-03-28
CVE-2013-0920 [HIGH] CWE-399 CVE-2013-0920: Use-after-free vulnerability in the extension bookmarks API in Google Chrome before 26.0.1410.43 all Use-after-free vulnerability in the extension bookmarks API in Google Chrome before 26.0.1410.43 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2013-2857P4HIGHCVSS 7.5≤ 27.0.1453.109v27.0.1453.0+79 more2013-06-05
CVE-2013-2857 [HIGH] CWE-416 CVE-2013-2857: Use-after-free vulnerability in Google Chrome before 27.0.1453.110 allows remote attackers to cause Use-after-free vulnerability in Google Chrome before 27.0.1453.110 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the handling of images.
nvd
CVE-2014-3196P4HIGHCVSS 7.5≤ 38.0.2125.72014-10-08
CVE-2014-3196 [HIGH] CWE-264 CVE-2014-3196: base/memory/shared_memory_win.cc in Google Chrome before 38.0.2125.101 on Windows does not properly base/memory/shared_memory_win.cc in Google Chrome before 38.0.2125.101 on Windows does not properly implement read-only restrictions on shared memory, which allows attackers to bypass a sandbox protection mechanism via unspecified vectors.
nvd
CVE-2013-0922P4HIGHCVSS 7.5≤ 26.0.1410.42v26.0.1410.0+40 more2013-03-28
CVE-2013-0922 [HIGH] CWE-264 CVE-2013-0922: Google Chrome before 26.0.1410.43 does not properly restrict brute-force access attempts against web Google Chrome before 26.0.1410.43 does not properly restrict brute-force access attempts against web sites that require HTTP Basic Authentication, which has unspecified impact and attack vectors.
nvd
CVE-2015-8479P4HIGHCVSS 7.5≤ 46.0.2490.862015-12-06
CVE-2015-8479 [HIGH] CWE-119 CVE-2015-8479: Use-after-free vulnerability in the AudioOutputDevice::OnDeviceAuthorized function in media/audio/au Use-after-free vulnerability in the AudioOutputDevice::OnDeviceAuthorized function in media/audio/audio_output_device.cc in Google Chrome before 47.0.2526.73 allows attackers to cause a denial of service (heap memory corruption) or possibly have unspecified other impact by triggering access to an unauthorized audio output device.
nvd
CVE-2018-6066P4MEDIUMCVSS 6.5fixed in 65.0.3325.146≥ unspecified, < 65.0.3325.1462018-11-14
CVE-2018-6066 [MEDIUM] CWE-200 CVE-2018-6066: Lack of CORS checking by ResourceFetcher/ResourceLoader in Blink in Google Chrome prior to 65.0.3325 Lack of CORS checking by ResourceFetcher/ResourceLoader in Blink in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2015-1271P4MEDIUMCVSS 6.8≤ 43.0.2357.1342015-07-23
CVE-2015-1271 [MEDIUM] CWE-119 CVE-2015-1271: PDFium, as used in Google Chrome before 44.0.2403.89, does not properly handle certain out-of-memory PDFium, as used in Google Chrome before 44.0.2403.89, does not properly handle certain out-of-memory conditions, which allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via a crafted PDF document that triggers a large memory allocation.
nvd
Google Chrome vulnerabilities | cvebase